Skip to main content
TrustRadius
Wireshark

Wireshark

Overview

What is Wireshark?

Wireshark is a free and open source network troubleshooting tool.

Read more
Recent Reviews

TrustRadius Insights

Wireshark, a widely utilized network traffic analysis tool, has proven to be invaluable for various user experiences and use cases. Cyber …
Continue reading

Indispensable tool

9 out of 10
October 31, 2022
Incentivized
Its port scans help you find the problem quickly. Recently I had to analyze a company because there was so much traffic on the network.
Continue reading

To Wireshark or not

9 out of 10
October 31, 2022
We use Wireshark in a multitude of ways. First, we troubleshoot connectivity issues with it, second, we use it for Firewall ruleset tests …
Continue reading
Read all reviews

Awards

Products that are considered exceptional by their customers based on a variety of criteria win TrustRadius awards. Learn more about the types of TrustRadius awards to make the best purchase decision. More about TrustRadius Awards

Return to navigation

Pricing

View all pricing

Wireshark

Free

On Premise

Entry-level set up fee?

  • No setup fee

Offerings

  • Free Trial
  • Free/Freemium Version
  • Premium Consulting/Integration Services
Return to navigation

Product Demos

Local and Remote Sniffing with Wireshark

YouTube

Wireshark demo (simple http)

YouTube

Saving Files From Wireshark

YouTube

Brim Demo

YouTube

How to Use Wireshark's Follow TCP Stream Feature

YouTube

Wireshark SIP Capture

YouTube
Return to navigation

Product Details

What is Wireshark?

Wireshark is a free and open source network troubleshooting tool.

Wireshark Technical Details

Deployment TypesOn-premise
Operating SystemsWindows, Linux, Mac
Mobile ApplicationNo

Frequently Asked Questions

Wireshark is a free and open source network troubleshooting tool.

Wireshark starts at $0.

Reviewers rate Support Rating highest, with a score of 10.

The most common users of Wireshark are from Mid-sized Companies (51-1,000 employees).
Return to navigation

Comparisons

View all alternatives
Return to navigation

Reviews and Ratings

(135)

Community Insights

TrustRadius Insights are summaries of user sentiment data from TrustRadius reviews and, when necessary, 3rd-party data sources. Have feedback on this content? Let us know!

Wireshark, a widely utilized network traffic analysis tool, has proven to be invaluable for various user experiences and use cases. Cyber security professionals rely on Wireshark for research and investigation, allowing them to check network traffic from applications and ensure there are no abnormalities. The software's versatility is demonstrated by its utilization in setting up Capture the Flag challenges, making it an engaging tool for recruiting purposes. Additionally, Wireshark is essential for monitoring network traffic and troubleshooting network-related issues, saving time and effort in problem-solving. It enables system administrators and network administrators to dissect network packets in detail, extract relevant network information, and quickly identify and resolve network problems. The software's free and open-source nature provides cost savings without compromising functionality, making it a preferred choice for users. Its graphical interface makes network packet analysis less cumbersome compared to command-line alternatives. Moreover, Wireshark aids in in-depth analysis of TCAP messages, debugging of network data exchange issues, investigating network issues and locating lost IPs on the network, troubleshooting site-to-site VPN tunnels, identifying unusual activity in network traffic, tracking specific users' data for detection of client/server connectivity issues, aiding in networking and security education with real-time lab environments, capturing and analyzing network traffic for automation purposes, verifying protocol usage, troubleshooting firewall ruleset tests, monitoring traffic patterns, locating desired information within the network using powerful filters, identifying handshake issue algorithm compatibility problems with database servers and clients, diagnosing issues with VOIP phone systems causing dropped calls due to packet loss, capturing network traffic for system information management purposes, addressing ping scan DOS attacks on external locations and severe broadcast storms caused by corrupted NIC drivers on the main network. The versatility of Wireshark extends to various organizations where it is used for network design, testing, operation as well as helping technicians analyze network traffic effectively during troubleshooting at client sites.

Affordable Price: Many users appreciate the low cost of Wireshark, as it provides powerful network analysis capabilities without the need for expensive software. Several reviewers have stated that Wireshark offers a good value for its price.

Packet Analysis Capabilities: The ability to capture, log, and analyze packet data is highly valued by users. Many reviewers have mentioned that this feature allows for detailed troubleshooting and monitoring of network traffic in their feedback on Wireshark.

Real-time Network Visibility: Users find the real-time network data visibility provided by Wireshark to be invaluable. Several customers have mentioned that this feature enables them to monitor network activity promptly and identify any issues or anomalies with ease.

Confusing User Interface: Some users have found the user interface of Wireshark to be confusing, suggesting that it can be improved to make it more user-friendly and intuitive.

Steep Learning Curve: The software has a steep learning curve, with new users finding it overwhelming to see all the columns and colors. This can make it challenging for them to navigate and understand the software.

Lack of User-Friendliness: While acknowledging that Wireshark is not primarily designed for those who are not comfortable with this type of software, some users still mention the lack of a more user-friendly interface. They suggest enhancing the UI/UX to make it more intuitive and easier to use.

Users of Wireshark have made several recommendations based on their experience with the software. The most common recommendations include utilizing the free version, seeking help and documentation online, and exploring all features and capabilities.

Many users recommend using the free version of Wireshark as it is considered a great tool for networking systems and packet analysis. Users appreciate its stability and open-source nature.

To effectively use Wireshark, users advise seeking help and documentation online. They suggest following tutorials and reading the new user guide to understand how to navigate the software's features.

Users also recommend spending time exploring all the features and capabilities of Wireshark, although it may seem overwhelming at first. By doing so, users can fully utilize this powerful network sniffing tool, particularly on Linux systems.

Overall, users consider Wireshark an excellent network packet analyzer that caters to the needs of both network engineers and beginners in network engineering. However, some users caution obtaining security approval before using the software. While they acknowledge that Wireshark may provide more information than expected, they still regard it as a valuable tool for their networking needs.

Attribute Ratings

Reviews

(1-3 of 3)
Companies can't remove reviews or game the system. Here's why
Drew Harrison | TrustRadius Reviewer
Score 8 out of 10
Vetted Review
Verified User
Incentivized
Wireshark was my go-to tool for capturing and analyzing network traffic while building automation technologies (web bots) for years. It allowed me to quickly see what headers, cookies, and data were being sent during web requests and responses. So I could quickly and accurately mimic the data for automation, and it made life so much easier to have all that data collected and presented in one decent interface.
  • Captures all kinds of packet data in network traffic
  • Save & restore captured packed data
  • Show errors and issues in levels below the HTTP protocol
  • Can't modify or manipulate things/data on the network (only records data)
  • A better interface would be nice - it's functional as-is, but it could use some polish
If you need to analyze packet data across your network and want the low-level details, Wireshark is perfect for the job. It records the necessary data and presents it in a way that's relatively easy to read, analyze, and understand. It's got a ton of features (more than most people will ever need). However, if you're simply interested in HTTP traffic, I believe Fiddler is a slightly better choice, as it is more explicitly geared towards the HTTP protocol.
  • I can't put a dollar amount on Wireshark's value or the ROI it has provided. Still, it has been an invaluable tool that has saved many, many hours of frustration when it comes to analyzing network traffic.
Fiddler has recently become my preferred network packet capturing tool, as it allows you to manipulate data for testing. Because I'm building automation software, this feature is invaluable to me. Otherwise, Wireshark is the better choice because it can capture ANY type of network traffic, which is crucial for network admins (along with people in other professions).
I don't believe Wireshark has "true" support as the software is open source. However, there is an active & friendly community around Wireshark that are more than happy to help answer questions. From a comprehensive Wiki and FAQ section on the site to the Ask a Question forum and bug tracker section, there's plenty of support options to make sure your questions and issues are addressed.
Score 10 out of 10
Vetted Review
Verified User
Incentivized
I use it as a systems information manager to capture traffic on the network and analyze the packets for various reasons. I have used it to find a ping scan from a wireless network that was DOS'ing an external location, and also have used it to pinpoint a system with a corrupted NIC driver that was causing a severe broadcast storm on our main network.
  • Packet capturing
  • Packet analysis
  • Traffic monitoring and reporting
  • It is beginner-friendly as far as installation, but it could use a tutorial.
  • Perhaps there is a way to do this already, but I haven't yet seen it. It would be nice if it could be integrated with a network package that could detect network anomalies, fire up an automated packet analysis, and send a report to an administrator.
It is invaluable for capturing and analyzing network traffic and identifying issues with devices that are either malfunctioning, or possibly even set up as rogue devices on a network. Using the data from a packet analysis combined with logs and MAC tables from various network devices, it can be used to find specifically where a device might be located. It's not a "set it and forget it" application, but it is well suited for on-the-spot analysis.
  • It has helped identify hardware malfunction issues that were leading to network downtime.
  • It has helped identify security issues on a network that helped in preventing an attack.
  • It has helped me get an overview coming into a network with no documentation so I could streamline our documentation and make our support process more efficient.
It is free compared to solarwinds deep packet software. It is easier to use than tcpdump or ettercap, and it has a much better presentation of the data. It's not as in depth as PRTG Network Monitor, but for an on the spot analysis, it is better for resource management and much quicker to set up and configure.
I haven't had to contact their official support because there is a HUGE amount of documentation and community support available. I imagine that one would be hard pressed to find many issues where they might need to contact actual support.
Score 10 out of 10
Vetted Review
Verified User
Incentivized
We use Wireshark whenever there is a need for deep-dive packet captures. We usually turn to Wireshark after we have done all other steps in general troubleshooting. Wireshark is being used by both the campus network teams, data center network teams, corporate systems team, and production systems team. It is a great tool not only for network engineers.
  • EXTENSIVE detail
  • Easy to run, even for non-networking individuals. Makes it so they can run a packet capture on their machine and send to the network team for analysis.
  • Lowcost
  • Packet capture files get extremely large, extremely quickly.
  • Sifting through packet capture can be arduous at times.
  • Sometimes it feels almost "too in-depth" and can be overwhelming to look at. Hard to know where to start looking.
Wireshark is a great tool to use after general network troubleshooting has taken place; checking subnet mask, default gateway, route table, etc. It can help identify breaks or hiccups in network communication, and narrow down where further investigation should be focused. It is not a good tool to use for general troubleshooting, you need to have a core knowledge of networking to find the tool valuable.
  • Packet Capture files can take lots of effort to sift through. Sometimes running multiple packet captures are required in order to catch the troubling behavior.
  • Packet Captures are extremely in-depth and can be used in troubleshooting as well as teaching.
  • Wireshark is a great way for network engineers to show the problem is elsewhere when the network is being blamed.
  • SolarWinds Netflow Traffic Analyzer
Wireshark is MUCH more in-depth and easy to use. Even though the files can get large and be a bit overwhelming, there are plenty of how-to articles and forums that can help you find the desired syntax for what you are looking for. Netflow Traffic Analyzer seems like a bit of an afterthought and doesn't hold a candle to the value Wireshark delivers.
I have never engaged Wireshark support directly. Whenever I would run into a question or needed to learn about a certain feature, I was able to find the information I was looking for on tech blogs and forum posts by other network engineers. The Wireshark community has been more than enough whenever I had issues.
Return to navigation